Skip to content

fix(security): update vulnerable release dependencies - #7

Merged
RadnoK merged 4 commits into
mainfrom
fix/security-deps-0.1.6
Sep 30, 2026
Merged

RadnoK merged 4 commits into
mainfrom
fix/security-deps-0.1.6

Conversation

@RadnoK

@RadnoK RadnoK commented Sep 30, 2026

Copy link
Copy Markdown
Member

The v0.1.5 CI security gate failed on fixable advisories in production image dependency brace-expansion@5.0.9 and the Next.js example's next@16.3.3. This prepares v0.1.6, applies pnpm 11's workspace override for brace-expansion@5.0.12, upgrades Next.js to 16.3.6, updates the lockfile, versioned docs/fixtures, and evaluation integrity records.\n\nVerified locally: frozen pnpm install, production pnpm audit, Next.js build, docs checks, and Helm documentation tests. Full release and eval suites are still running; CI performs the cross-platform/release-image checks.

@RadnoK
RadnoK force-pushed the fix/security-deps-0.1.6 branch from 0624a24 to 33fc724 Compare September 30, 2026 19:58
@RadnoK
RadnoK merged commit 77625de into main Sep 30, 2026
14 checks passed
@RadnoK
RadnoK deleted the fix/security-deps-0.1.6 branch September 30, 2026 20:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant